US11227049B1ActiveUtility

Systems and methods of detecting malicious PowerShell scripts

Assignee: USAAPriority: Dec 2, 2016Filed: Feb 20, 2020Granted: Jan 18, 2022
Est. expiryDec 2, 2036(~10.4 yrs left)· nominal 20-yr term from priority
H04L 2101/622H04L 61/5007G06F 21/564G06F 21/563H04W 4/02H04L 63/1416H04L 63/20G06F 2221/034H04L 67/02G06F 21/554H04L 61/6022H04L 61/2007
78
PatentIndex Score
1
Cited by
13
References
20
Claims

Abstract

Disclosed herein are systems and methods of executing scanning software, such an executable software program or script (e.g., PowerShell script), by a computing device of an enterprise, such as a security server, may instruct the computing device to search all or a subset of computing devices in an enterprise network. The scanning software may identify PowerShell scripts containing particular malware attributes, according to a malicious-code dataset. The computing system executing the scanning software may scan through the identified PowerShell scripts to identify particular strings, values, or code-portions, and take a remedial action according to the scanning software programming.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
       1. A computer-implemented method comprising:
 periodically querying, by a server, at least one data repository accessible to one or more computers; 
 when the server identifies a task automation and configuration management software script, querying, by the server, the task automation and configuration management software script according to a malicious-code dataset comprising a plurality of malware attributes containing at least one of a malicious task automation and configuration management software script, a malicious task automation and configuration management software command line, and a malicious task automation and configuration management software argument; and 
 in response to the computer identifying that the data repository accessible to at least one infected computer accessing the at least one task automation and configuration management software script containing code portion that matches at least a part of the plurality of malware attributes in the malicious-code dataset, causing, by the server, the at least one infected computer to terminate any connection with at least one other computer within the one or more computers. 
 
     
     
       2. The method of  claim 1 , wherein data repository hosts one or more task automation and configuration management software files configured to be executed on the one or more computers. 
     
     
       3. The method of  claim 1 , wherein the task automation management and configuration management software scrip corresponds to a task automation and configuration management software command or a task automation and configuration management software argument. 
     
     
       4. The method of  claim 1 , wherein the one or more computers are connected via an enterprise network. 
     
     
       5. The method of  claim 1 , wherein the data repository is a hard drive accessible to one computer. 
     
     
       6. The method of  claim 1 , wherein a frequency value corresponding to how often the data repository is scanned is received from a client computing device. 
     
     
       7. The method of  claim 1 , wherein the code portion matching at least the part of the plurality of malware attributes is configured to instruct a secondary file to execute one or more commands. 
     
     
       8. The method of  claim 7 , wherein the secondary file is a dynamic link library file. 
     
     
       9. The method of  claim 1 , wherein the malicious-code dataset further comprises a list of malicious commands executed by one or more dynamic libraries files. 
     
     
       10. The method of  claim 1 , further comprising:
 generating, by the server, a notification containing a unique identifier associated with the at least one infected computer. 
 
     
     
       11. A computer system comprising:
 a plurality of computers, each computer accessing at least one hard drive hosting a file system configured to store a plurality of task automation and configuration management software script; and 
 a server coupled to the plurality of computers, the server comprising a processor and non-transitory computer readable medium comprising machine-readable instructions configured to be executed by the processor to:
 periodically query at least one data repository accessible to one or more computers within the plurality of computers; 
 when the server identifies at least one of a task automation and configuration management software script, query the task automation and configuration management software script according to a malicious-code dataset comprising a plurality of malware attributes containing at least one of a malicious task automation and configuration management software script, a malicious task automation and configuration management software command line, and a malicious task automation and configuration management software argument; 
 in response to the computer identifying that the data repository accessible to at least one infected computer accessing the at least one task automation and configuration management software script containing code portion that matches at least a part of the plurality of malware attributes in the malicious-code dataset, cause the at least one infected computer to terminate any connection with at least another computer within the one or more computers. 
 
 
     
     
       12. The computer system of  claim 11 , wherein data repository hosts one or more task automation and configuration management software files configured to be executed on the one or more computers. 
     
     
       13. The computer system of  claim 11 , wherein the task automation and configuration management software scrip corresponds to a task automation and configuration management software command or a task automation and configuration management software argument. 
     
     
       14. The computer system of  claim 11 , wherein the one or more computers are connected via an enterprise network. 
     
     
       15. The computer system of  claim 11 , wherein the data repository is a hard drive accessible to one computer. 
     
     
       16. The computer system of  claim 11 , wherein a frequency value corresponding to how often the data repository is scanned is received from a client computing device. 
     
     
       17. The computer system of  claim 11 , wherein the code portion matching at least the part of the plurality of malware attributes is configured to instruct a secondary file to execute one or more commands. 
     
     
       18. The computer system of  claim 17 , wherein the secondary file is a dynamic link library file. 
     
     
       19. The computer system of  claim 11 , wherein the malicious-code dataset further comprises a list of malicious commands executed by one or more dynamic libraries files. 
     
     
       20. The computer system of  claim 11 , wherein the server is further configured to:
 generate a notification containing a unique identifier associated with the at least one infected computer.

Join the waitlist — get patent alerts

Track US11227049B1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.